ISACA Finds AI Adoption Outpaces Cyber Readiness in Indian Firms
In light of recent news revealing several instances of rogue AI model behavior, new research from ISACA finds concerning news about AI security. While AI is being heavily leveraged within cybersecurity teams, only 21 percent of organizations in India indicate they conduct AI-specific response exercises regularly, according to new research from ISACA.
ISACA’s 2026 State of Cybersecurity survey report, sponsored by Wolters Kluwer TeamMate, garnered responses from more than 1,800 global cybersecurity professionals including 147 cybersecurity professionals in India. The report explored trends in cybersecurity hiring, staffing, and budgets, while focusing on cyberrisk and threats, cybersecurity operations, and the role of AI in cybersecurity work.
This 12th annual survey finds that nearly half (49 percent) of enterprises in India have not conducted any AI-related incident response exercises—including top types cited by respondents like AI-enabled phishing, fraud or social engineering (33 percent), AI-related incidents such as sensitive data exposure through AI systems (32 percent), and unauthorized access to AI systems, models, or data (32 percent). Though, 20 percent say that AI incident response is included in broader cyber incident response exercises and 13 percent plan to conduct AI-specific exercises in the future.
The gaps in planning at enterprises also extend to AI incident playbooks. Over a third (35 percent) of India-based respondents either don’t know whether their organization has established them or mention their organization does not have them.
AI adoption in India is moving at a fast pace and this research is a wake-up call for India's cybersecurity teams that speed without readiness is a risk in itself
Increasingly, AI is also impacting the skills required in cybersecurity roles. Thirty—four percent of India-based respondents cite LLM SecOps as a skill gap among cybersecurity professionals, a 10-point increase from 2025.
"AI adoption in India is moving at a fast pace and this research is a wake-up call for India's cybersecurity teams that speed without readiness is a risk in itself. Many enterprises are automating threat detection and routine security work at a rapid pace, yet most still lack tested playbooks for AI-specific incidents like model tampering, data exposure, or AI-powered social engineering. As AI investment continues to scale across Indian organizations, closing the gap between adoption and preparedness is critical through regular incident exercises and dedicated LLM SecOps training. This needs to become a boardroom priority, not just a security issue," says RV Raghu, ISACA Ambassador & Director, Versatilist Consulting India Pvt. Ltd.
Also Read: Salesforce Sees India Moving Toward Broader Enterprise AI Adoption
Cybersecurity professionals in India are now even more hands-on with AI implementation and governance within their organizations, with more than half (51 percent) now involved in developing, onboarding or implementing AI solutions, up from 46 percent in 2025 and 27 percent in 2024. Additionally, 52 percent of Indian respondents say that they or someone from their team were involved in policy governing development for the use of AI in their organization.



